Last updated: 23 September 2026
Who we are
CrysMed is operated by Crysmed Healthcare FZE, registered in the Sharjah Publishing City Free Zone, United Arab Emirates. This policy explains how we collect, use, share and protect personal information across crysmed.ae and our related services, and how you can exercise your rights over it.
Information we collect
What we collect depends on how you use CrysMed:
- Account details. Name, email address, mobile number, password (stored as a secure hash, never in plain text), country/emirate/city, and date of birth if you choose to add it.
- Provider or corporate details. If you register a facility or a company account: facility or company name, licence and registration numbers, business address, contact person details, and any documents you upload for verification (e.g. trade licence, facility licence, ID).
- Health information (optional). If you choose to complete a Health Profile, you may add allergies, chronic conditions, current medicines, blood group, a primary doctor/facility, and an emergency contact. This is provided entirely at your discretion and is never required to use CrysMed.
- Bookings and transactions. Orders, appointments, vouchers, membership and course activity. Payments are processed by Stripe; we do not store your full card details ourselves.
- Communications. Messages you send us (e.g. through the Contact form), and a record of the verification codes, receipts and account notices we send by email, SMS or WhatsApp.
- Consent records. Which notices you've accepted (Terms, Privacy Notice, marketing, WhatsApp updates) and when, so we can show you your current status and let you withdraw at any time.
- Technical information. The IP address a registration was submitted from, used only for basic abuse prevention (e.g. limiting repeated sign-ups from the same source).
We do not currently use advertising or analytics tracking cookies on crysmed.ae.
How we use it
- To create and secure your account, and verify your email and mobile number.
- To provide the service you've asked for — bookings, orders, memberships, courses, provider or corporate listings.
- To send account, security and transactional messages (verification codes, receipts, status updates).
- To send WhatsApp or email updates you've separately opted in to.
- To review and verify provider and corporate registrations before they go live.
- To meet our own legal, accounting and fraud-prevention obligations.
Who we share it with
- Stripe, to process payments. We don't receive or store your full card number.
- Meta (WhatsApp Business Platform), to deliver verification codes and messages you've opted in to.
- The provider or facility you book with, limited to what's needed to fulfil that booking.
- Our hosting infrastructure, to run the service. We don't sell personal information to third parties.
How long we keep it
We keep account information for as long as your account is active. If you close your account or ask us to delete it, we anonymise your identifying details (name, email, mobile) and deactivate the account. Some records are kept for longer where we're required to — transaction, invoice and payment records, fraud and audit records, records relevant to an open dispute, and records of consent or its withdrawal — consistent with our accounting and legal obligations.
Your rights
You can exercise these rights directly from your account, under My Account → Privacy & Consent:
- Access — request a copy of the information we hold about you.
- Correction — ask us to fix information that's wrong or out of date.
- Deletion — ask us to close and anonymise your account.
- Withdraw consent — turn off marketing or WhatsApp updates at any time, with immediate effect.
Access, Correction and Deletion requests go through a short verification step before a member of our team reviews and actions them — this protects your account from being changed by someone else pretending to be you. You can also reach us directly at the email below.
Keeping your information secure
Passwords are stored as salted hashes, not plain text. Sign-in to sensitive account types (providers, corporate accounts) requires a second verification step. We restrict who on our team can access personal data to what's needed for their role.
Children
CrysMed is intended for adults arranging their own or their family's healthcare. It isn't directed at children, and we don't knowingly collect information directly from children.
Changes to this policy
We may update this policy as CrysMed's services change. We'll update the date at the top of this page when we do.
Contact us
Crysmed Healthcare FZE
Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
Email: info@crysmed.ae